LIVE FEED
228 events · 13 sources · newest first
Events in view
228
all sources
Critical
0
severity
Active sources
13
collectors
Last sync
2026-08-28 18:00
UTC
All sources
NVD CVE · 1796CISA KEV · 1686News · 435CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-03-09
NVD CVE
CVE-2026-25960: vLLM is an inference and serving engine for large language models (LLMs). The SS
HIGH
vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in the load_from_url_async method due to inconsistent URL parsing...
2026-03-07
NVD CVE
CVE-2026-29186: Backstage is an open framework for building developer portals. Prior to version
HIGH
Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techdocs-node package...
2026-01-27
NVD CVE
CVE-2026-24881: In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an
HIGH
In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily...
2026-01-21
NVD CVE
CVE-2026-22807: vLLM is an inference and serving engine for large language models (LLMs). Starti
HIGH
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without...
2026-01-20
NVD CVE
CVE-2026-23876: ImageMagick is free and open-source software used for editing and manipulating d
HIGH
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage)...
2026-01-09
NVD CVE
CVE-2025-13761: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6
HIGH
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an ...
2026-01-07
NVD CVE
CVE-2025-69264: pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted depend
HIGH
pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution...
2026-01-04
NVD CVE
CVE-2025-3653: Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an improper ac
HIGH
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an improper access control vulnerability that allows unauthorized device manipulation by accepting arbitrary serial numbers without ownership...
2025-06-05
NVD CVE
CVE-2025-5635: A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This
HIGH
A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of the component PLS Command Handler. The manipulation leads to buffer overflow. The attack can be...
2025-05-29
NVD CVE
CVE-2025-5331: A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as criti
HIGH
A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown code of the component NLST Command Handler. The manipulation leads to buffer overflow. The...
2025-01-14
NVD CVE
CVE-2024-48884: A improper limitation of a pathname to a restricted directory ('path traversal')
HIGH
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3,...
2024-11-27
NVD CVE
CVE-2024-11667: A directory traversal vulnerability in the web management interface of Zyxel ATP
HIGH
◈ 2 sources · orig. NVD CVE
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series...
2024-09-10
NVD CVE
Azure Stack Hub Elevation of Privilege Vulnerability
2024-09-10
NVD CVE
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
2024-09-10
NVD CVE
Microsoft SQL Server Elevation of Privilege Vulnerability
2024-09-10
NVD CVE
CVE-2024-38194: An authenticated attacker can exploit an improper authorization vulnerability in
HIGH
An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network.
2024-09-10
NVD CVE
Windows TCP/IP Remote Code Execution Vulnerability
2024-09-10
NVD CVE
Windows Remote Desktop Licensing Service Spoofing Vulnerability
2024-09-10
NVD CVE
Microsoft SQL Server Elevation of Privilege Vulnerability
2024-09-10
NVD CVE
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
2024-08-08
NVD CVE
CVE-2024-42256: In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix s
HIGH
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix server re-repick on subrequest retry
When a subrequest is marked for needing retry, netfs will call
cifs_prepare_write() which will make...
2024-06-27
NVD CVE
CVE-2024-35260: An authenticated attacker can exploit an untrusted search path vulnerability in
HIGH
An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
2024-04-25
NVD CVE
CVE-2024-22373: An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStream
HIGH
An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An...
2024-01-30
NVD CVE
CVE-2024-21488: Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command
HIGH
Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the...
2023-08-08
NVD CVE
Windows System Assessment Tool Elevation of Privilege Vulnerability
2023-08-08
NVD CVE
Windows Mobile Device Management Elevation of Privilege Vulnerability
2023-07-11
NVD CVE
CVE-2023-3617: A vulnerability was found in SourceCodester Best POS Management System 1.0. It h
HIGH
A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been classified as critical. This affects an unknown part of the file admin_class.php of the component Login Page. The manipulation...
2021-12-03
NVD CVE
CVE-2021-23758: All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted
HIGH
◈ 2 sources · orig. NVD CVE
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
ajaxnetajaxnet-professionalajaxprocisa-kevcve-2021-23758deserializationendlife